You can invite Alibaba Cloud accounts that are outside your Resource Directory to join it as members. This enables you to centrally manage all your accounts and resources. If you want to create a new member account instead of inviting an existing account, see View the basic information about a resource directory.
Prerequisites
You can invite an Alibaba Cloud account only if its enterprise real-name verification information matches that of the management account. If your organization has multiple subsidiaries with different verification information, contact your account manager for assistance.
Ensure that the invitee does not have any invitations pending confirmation. Otherwise, you cannot invite the account again.
Ensure that you send no more than 20 invitations per day.
Ensure that you have no more than 20 invitations in the Pending Confirmation state.
Procedure
-
Log on to the Resource Management console with a management account.
In the left-side navigation pane, choose .
Click Invite Member.
In the Invite Member dialog box, enter the required information, review and select the risk notice, and then click OK.
Parameter
Description
Account ID or logon email address
Account ID: To find an account ID, see How do I find my Alibaba Cloud account ID?.
Logon email address: The email address that you used to register the account. If an account does not have a logon email, use its account ID.
To invite multiple accounts, enter their account IDs or logon email addresses, separated by commas.
Remarks
Enter a remark for the invitation. This helps the invitee verify the invitation's authenticity and respond faster.
Tag
Add a tag to the member for easier filtering and management.
Parent Folder
By default, the invited member is placed in the Root folder. You can click Modify to move the member to a different folder. You can also change the folder after the member accepts the invitation.
Next steps
After receiving the invitation, the invitee can view it on the Resource Management console, by email, or through an internal message. The invitee can then review the invitation and decide whether to accept or decline it. For details on how to respond to an invitation in the Resource Management console, see Respond to an invitation.
If you invite an account using its account ID, the system sends a confirmation email to the logon email address of the account.
If you invite an account using its logon email address, the system sends a confirmation email to that address.
Once an invited account joins the Resource Directory, it becomes a member and is managed centrally as follows:
By default, the invited account's original name becomes its display name and account name within the Resource Directory. The management account can change the member's display name, but not its account name.
Resource Directory automatically creates a RAM role named ResourceDirectoryAccountAccessRole for the member. The management account assumes this role for centralized management.
View resources of a member account
After a member joins the Resource Directory, complete the following steps to view the resources of the member account:
In the Resource Management console, choose Resource Center > Cross-account Resource Search, and then enable cross-account resource search. After you enable this feature, the system builds Resource Center for all members in the Resource Directory. For more information, see Enable cross-account resource search.
If a RAM user needs to use cross-account resource search, attach the following system policies to the RAM user:
AliyunSTSAssumeRoleAccess: allows the RAM user to call theAssumeRoleoperation of Security Token Service (STS).AliyunResourceDirectoryFullAccess: allows the RAM user to manage the Resource Directory service.
FAQ
Why can't I invite members after logging in with my Alibaba Cloud account?
The management account of a Resource Directory is not necessarily the Alibaba Cloud account that you are currently logged in with. Only the management account designated when the Resource Directory was enabled has the permission to invite members. If you cannot perform the invitation operation or receive a permission error after logging in, your current account is not the management account of the Resource Directory.
Solution: Check your organization's internal records or contact the relevant administrator to confirm the management account of the Resource Directory. Then, log on with that management account to perform the invitation operation.
Why don't some member accounts appear in the account sharing list in the User Center?
This issue usually occurs because the account has not been formally invited to join the Resource Directory, or the process of joining has not been completed. Follow the Procedure section in this topic to invite the unmanaged account to join the Resource Directory. After the member successfully joins, the account appears in the account sharing list in the User Center, where you can allocate costs to it.
What do I do if the error message The TargetEntity is invalid is displayed when I invite a member?
The account invited to join a Resource Directory must be an Alibaba Cloud account (root account). RAM users and member accounts cannot be invited. The The TargetEntity is invalid error is returned because you entered the logon name of a member account or a RAM user.
Use the UID of the target Alibaba Cloud account or the logon email address used to register the account to send the invitation again.